Windows exploit for sale for $220.000

Someone is trying at the moment to sell a Windows exploit on the dark web for $220.000. The exploit specifically targets Windows Remote Desktop Services and gives the attacker system-level privileges on a compromised computer.0day bw

A relatively new user, who goes by the name “Kamirmassabi,” recently posted an ad in the malware and exploits section of an underground forum. The ad specifically states that the vulnerability is a “zero day” and invites interested buyers to contact via private message to discuss the purchase.

See more articles from iGuRu.gr when you search for news on Google.

The vulnerability itself is documented as CVE-2026-21533 . It allows an attacker to change a specific service configuration registry key in the TermService protocol and elevate their privileges to the system level on a targeted computer.

However, for the exploit to work, the attacker would already need to have low-privilege authentication access to a local machine. This means that hackers would first need to gain initial access to a targeted system, possibly using one of the established phishing schemes, to trick targeted users into downloading malicious files that would give the attacker access to the machine.

What's interesting about this particular exploit is that Microsoft has already patched it. The vulnerability was fixed with February's Patch Tuesday. The threat had a huge reach, affecting various versions of Windows 10 and Windows 11, as well as Server versions from Windows Server 2012 to Windows Server 2025.

Attackers are likely betting that many corporate networks have not yet updated their systems and are looking for an opportunity to strike there. If the security hole had not been patched, the price on the dark web would be much higher.

We are seeing an emerging trend in the cybersecurity space, where malicious users have started acting as vendors, rather than carrying out the exploits themselves.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).